Executive brief
A vulnerability was identified in the Linux kernel's digital video broadcasting (DVB) networking component. This flaw allows a remote attacker to send specially crafted network data that triggers an out-of-bounds memory access. In practice, this could lead to a complete system crash or allow an attacker to execute unauthorized code, potentially compromising the entire server or device.
Technical details
An out-of-bounds (OOB) read vulnerability exists in the handle_one_ule_extension() function within drivers/media/dvb-core/dvb_net.c. The vulnerability occurs because the 'htype' index, derived from network-controlled data (ule_sndu_type & 0x00FF), is used to access the ule_mandatory_ext_handlers[] and ule_optional_ext_handlers[] tables without proper bounds checking. While the tables contain 255 elements, the derived index can reach 255, leading to an OOB read. Because these tables store function pointers, an attacker can potentially trigger the execution of an out-of-bounds value as a function pointer. This can be exploited remotely via network packets to achieve arbitrary code execution or a kernel panic. The issue has been patched by adding explicit bounds checks against the array size.
Affected products
- Linux Linux Kernel from 2.6.12-rc2 up to 5.10.253, 5.15.203, 6.1.167, 6.6.130, 6.12.78, 6.18.19, 6.19.9
Timeline
- 2026-04-06: disclosed: Initial publication of the vulnerability advisory.
- 2026-04-06: advisory
- 2026-03-25: patched: Patches committed to various stable kernel branches.
References
- https://git.kernel.org/stable/c/145e50c2c700fa52b840df7bab206043997dd18e
- https://git.kernel.org/stable/c/1a6da3dbb9985d00743073a1cc1f96e59f5abc30
- https://git.kernel.org/stable/c/24d87712727a5017ad142d63940589a36cd25647
- https://git.kernel.org/stable/c/29ef43ceb121d67b87f4cbb08439e4e9e732eff8
- https://git.kernel.org/stable/c/8bde543d2a5f935ba2a6a6325a2e02f8a9256fbe
- https://git.kernel.org/stable/c/b2bd2ee73b697c177157bba534e1b1064c2e66a0
- https://git.kernel.org/stable/c/e51238718217c4abdb3ccc3b0c0cde265c7ec629